mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
Google rejected the Health Connect declaration a second time with the same code as the first: "Use of permission is not a permitted/valid use case ... or potentially engages in a prohibited use." The declaration was not what failed. The My Fitness pivot rewrote docs/health-connect-play-declaration.md and PRIVACY.md but never touched the strings behind HealthConnectRationaleScreen - the screen the declaration points the reviewer at, and the one Health Connect itself opens for ACTION_SHOW_PERMISSIONS_RATIONALE. It still carried the rejected first submission verbatim: "Amethyst reads finished workouts so it can pre-fill a workout post for you ... so the people who follow you can see what you did." That is the prohibited "publicly displaying or socially sharing sensitive data", presented in-app as the official justification for the permission. Three further contradictions on the same screen: every per-permission bullet justified the data type by what it puts in the post rather than by the statistic My Fitness renders; it claimed a 7-day window and "only while the Workouts composer is open" against the 28 days and My Fitness the declaration claims (WorkoutStats.WINDOW_DAYS = 28 drives the dashboard, LOOKBACK_DAYS = 7 only ever drove the composer); and My Fitness was not named anywhere on it. The composer's permission card had the same problem - it was titled "Share your workouts". Both surfaces now tie every permission to a statistic the dashboard shows the user, state the 4-week window and both screens that read, name My Fitness, and describe publishing only under "What Amethyst does not do" as an optional, per-item, explicitly-confirmed action. The translated copies of the 13 changed strings are deleted so every locale falls back to the corrected English until Crowdin re-translates, rather than keeping the rejected wording live in 7 languages. Also records the root cause in the declaration doc, and fixes the reviewer walkthrough to log a workout before opening the dashboard - a review device's Health Connect database is empty, and an empty dashboard demonstrates none of the statistics these permissions serve. Verified: the merged playRelease manifest declares exactly the 7 android.permission.health.* entries and no ACTIVITY_RECOGNITION or BODY_SENSORS leaked in from any dependency, so this was never a manifest/declaration mismatch. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TPShPiTfg16yesupcLgyqf